vendor:
Firefox
by:
Unknown
7.5
CVSS
HIGH
Code Execution
94
CWE
Product Name: Firefox
Affected Version From: <= 1.5.0.4
Affected Version To: 1.5.0.4
Patch Exists: YES
Related CWE: CVE-2006-xxxxx
CPE: a:mozilla:firefox:1.5.0.4
Platforms Tested: Windows 2000 SP4, Windows XP SP4, Gentoo Linux
2006
Firefox <= 1.5.0.4 Javascript navigator Object Code Execution PoC
This vulnerability allows an attacker to execute arbitrary code on the target system using the navigator object in JavaScript. The exploit was tested on Firefox 1.5.0.4 on Windows 2000 SP4, Windows XP SP4, and Gentoo Linux. The bug was reported by TippingPoint and fixed in the latest release (1.5.0.5) of Mozilla Firefox. The exploit attempts to launch 'calc.exe' on Windows systems and 'touch /tmp/METASPLOIT' on Linux systems.
Mitigation:
Upgrade to the latest version of Mozilla Firefox (1.5.0.5) to fix this vulnerability.